2 results (0.002 seconds)

CVSS: 9.8EPSS: 42%CPEs: 1EXPL: 2

16 Feb 2006 — SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field). • http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0358.html •

CVSS: 9.8EPSS: 17%CPEs: 1EXPL: 3

11 Jan 2006 — SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field. NOTE: This is a different vulnerability than CVE-2005-3792. • https://www.exploit-db.com/exploits/27058 •